Laravel Passport Patches Machine-to-Human Authentication Bypass
ID: 9734a8ac-2b82-5fdc-9e30-1ebbc73c30ac
STIX ID: report--9734a8ac-2b82-5fdc-9e30-1ebbc73c30ac
Feed Name: securityonline.info
Threat Score
Laravel Passport CVE-2026-39976 (CVSS 7.1) details an authentication bypass in TokenGuard where client_credentials tokens may be resolved to actual user accounts if client and user IDs collide (notably when Passport::$clientUuids is disabled). The issue can let machine-to-machine tokens act with user privileges; upgrade to v13.7.1+ or disallow the client_credentials grant as interim mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
